Swedish regulator penalizes IT firm for security gaps behind massive data breach

Sweden's data protection authority IMY fined IT provider Miljödata approximately $183,000 for failing to implement adequate security measures that led to a cyberattack in August 2025. The breach exposed sensitive personal data of 2.2 million people, including identity numbers and school records, which was later leaked online. IMY found the company lacked proper software vetting and real-time monitoring, violating GDPR Article 32(1).
The cyberattack on Miljödata occurred on August 25, 2025, disrupting IT services across more than 200 Swedish regions and exposing records of 2.2 million individuals. The stolen data included personal identity numbers, contact details, sickness absence records, rehabilitation notes, and school incidents involving minors. The attackers initially demanded 1.5 Bitcoin (about $168,000) to prevent publication, but later leaked the information on the dark web under the alias "Datacarry."
IMY's investigation, launched in November 2025, determined that Miljödata failed to properly vet newly installed software and lacked automated real-time monitoring to detect intrusions. This negligence violated GDPR Article 32(1), resulting in the $183,000 fine. The regulator also noted that investigations into two municipalities and one region connected to the attack are still ongoing, meaning additional penalties could be issued against those public entities.
This penalty underscores the serious financial and reputational risks of inadequate security hygiene for vendors handling sensitive public-sector data. The breach affected millions, including minors, so affected individuals could face long-term consequences such as identity theft and privacy violations. IMY's ongoing probes into municipalities suggest accountability may extend beyond the vendor, potentially prompting stricter procurement standards and more rigorous oversight of third-party IT providers. This could lead to higher compliance costs for companies, but also stronger protections for citizens' personal information.